Disclosure summary
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with str.splitlines() and accepts the last value for duplicate keys. An attacker who influences --prompt, VIRTUALENV_PROMPT, or configuration input can insert a recognized line boundary and additional keys, including home, causing consumers to use an attacker-selected base interpreter or corrupted environment metadata. The security impact requires prompt input from outside the operator's trust boundary; directly supplied prompt content primarily corrupts the operator's own environment. This issue is fixed in version 21.7.11.
Source-reported weakness categories
CWE-93
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-9h9j-4vrj-gf7g
Open original source · Updated Sep 30, 2026
virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection
Source severity: MEDIUM / 5.8
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | virtualenv | 21.7.11 |
NIST National Vulnerability Database · NVD-CVE-2026-102938
Open original source · Updated Sep 30, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
PUBLISHED 2026-09-29T17:17:19-04:00
MODIFIED 2026-09-30T16:17:25-04:00
INGESTED 2026-10-06T11:43:05-04:00